LWA-2026-11850 confirmed malware

mcp-consultasdeveiculos@0.0.1

Malicious code in mcp-consultasdeveiculos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package is a code-less placeholder (package.json + README only, no code, no install scripts) that squats the name mcp-consultasdeveiculos, which is referenced in a third-party project's public documentation as the planned distribution channel (npx -y mcp-consultasdeveiculos-client --token ...) for an MCP client that receives users' API tokens. The package presents itself as a "security research placeholder" reserving the name, but the name squatting reserves a namespace tied to a related client package that harvests API tokens, enabling dependency-confusion / name-confusion abuse against users who install the client expecting the legitimate project's code.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 08:24 AM
analyzed
Sep 3, 2026, 08:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.